SapphireOne Achieves ATO Operational Security Framework Compliance

ATO-Operational Security Framework

In a significant advancement reinforcing its commitment to enterprise-grade data security,
SapphireOne is pleased to announce official compliance with the Australian Taxation Office’s Operational Security Framework (OSF). This achievement positions SapphireOne as a trusted Digital Service Provider (DSP), certified to manage client, financial, and business information within a secure and regulated environment.

The OSF is a strict ATO-mandated framework that outlines security requirements for DSPs interacting with ATO digital services, transferring tax-related data, or integrating with government endpoints. Compliance is essential for software providers managing sensitive taxpayer and personnel information, particularly within enterprise settings where accurate financial management, Payroll/HR processing, and audit transparency are critical.

Following a comprehensive security assessment, SapphireOne achieved OSF compliance under Category D – the highest classification level available. This confirms that SapphireOne
meets or exceeds the ATO’s most rigorous technical, procedural, and personnel-based security standards. It also demonstrates the effectiveness of SapphireOne’s integrated ERP, CRM, payroll / HR, asset management and accounting software in managing data within a securely governed IT environment.

For our client organisations, this compliance offers confidence that information processed by SapphireOne – including financial data, Payroll/HR records, expense management, and reporting – is managed in accordance with the ATO’s DSP security expectations. This is particularly valuable for those in regulated industries or those handling large volumes of sensitive operational data.

SapphireOne’s Category D certification includes verified practices such as audit logging, multi-factor authentication, ISO 27001:2022 alignment, encryption of data in transit, entity validation, personnel security, continuous monitoring, and supply chain transparency. These controls collectively ensure that access is restricted to authorised SapphireOne users, risks are monitored proactively, and SapphireOne processes remain fully auditable.

This compliance milestone highlights SapphireOne’s long-standing focus on security, compliance, and transparency. With the next ATO review scheduled for August 2026, clients can be assured of continued governance and oversight across all core functions – including Accounts, Inventory, Job Projects, Payroll/HR, assets and Management modes.

Organisations seeking secure and scalable ERP solutions can rely on SapphireOne for its comprehensive functionality and long-standing commitment – since 1986 – to operating in accordance with national standards for data protection and service integrity.